HashiCorpCVE-2026-87993
HashiCorp Tooling: information disclosure
High7.7CVE-2026-87993 · Published Sep 10, 2026
The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task events. This vulnerability (CVE-2026-87993) is fixed in consul-template 0.43.0.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Tooling Product | >= 0.27.2, < 0.43.0 | 0.43.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-532
More HashiCorp advisories
All HashiCorp| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 15 | HashiCorp Shared library: privilege escalation | Medium6.7 | 2.2.4 |
| Sep 10 | Consul and Consul Enterprise are vulnerable to an authorization bypass in the... | High7.1 | 2.0.4+1 more |
| Sep 10 | HashiCorp Consul: improper authorization | High8.3 | 2.0.4+1 more |
| Sep 10 | HashiCorp Consul: denial of service | Medium6.5 | 2.0.4+1 more |
| Sep 10 | HashiCorp Consul: improper authorization | Medium5.4 | 2.0.4+1 more |
| Aug 24 | HashiCorp Vault: insecure direct object reference | Medium6.8 | 2.0.4+1 more |